# Repository inventory evidence Captured: 2026-08-02 ## Scope and worktree - Branch: `release-readiness`, tracking `origin/release-readiness`. - Pre-existing user changes preserved: deleted tracked `.agent.md`; untracked `AGENTS.md`. - Audit-created paths: `docs/audits/` only. - Tracked-file distribution: 301 documentation files, 194 API files, 171 frontend files, 67 API-test files, 13 AI/tool files, 12 scripts, and 6 deployment files. ## Executable components | Component | Implementation | Responsibility | |---|---|---| | Browser client | `job-tracker-ui/` — React 19, TypeScript, MUI, React Router inside a Next.js static-export shell | Public landing/auth pages and authenticated job, career, CV, email, settings, and administration workflows | | API host | `JobTrackerApi/` — ASP.NET Core / .NET 9 | Authentication, authorization, REST endpoints, application workflows, data/file access, integrations, and hosted services | | Data layer | EF Core 9; SQLite default or Pomelo MariaDB/MySQL | Identity and tenant-owned job, profile, CV, correspondence, attachment, AI, and workflow state | | AI sidecar | `tools/summarizer/` — FastAPI, Transformers, OCR/document parsers | Local summaries and extraction; routes selected generation calls to Ollama, Gemini, or Groq | | Background processing | Seven hosted services in the API process | Backups, rules, reminders, daily export, enrichment, AI readiness probing, and queued CV processing | | Security fixture tool | `tools/hostile-fixture-db/` | Generates synthetic hostile database fixtures for local authorization testing | | Delivery | Dockerfiles, Docker Compose, nginx, `deploy/deploy.sh`, Gitea Actions | Builds, health checks, backup-gated deployment, and direct-to-production replacement after CI | ## External boundaries - Authentication: local ASP.NET Identity/JWT/cookie sessions; Google and Microsoft ID-token exchange/linking; TOTP 2FA. - Mail: Gmail OAuth/API, Microsoft Graph, IMAP, and SMTP. Audit tests must mock these boundaries. - Billing and abuse prevention: Stripe hosted flows/webhook and Cloudflare Turnstile. - Job discovery/import: NAV feed and site-specific URL parsers for Finn, LinkedIn, and Jobbnorge; optional LibreTranslate. - AI: private sidecar; Ollama locally or Gemini/Groq when configured. - File/PDF: local data-root storage and headless Chromium PDF export. ## Data ownership and trust boundaries - `ApplicationUser` is the identity root. - Tenant entities use `OwnerUserId`; EF global query filters deny access when the current user is absent and scope reads to that owner. - Several child entities rely on filtered parent navigation or explicit owner predicates rather than their own owner column. - Public CV is the main anonymous data-release boundary and requires an explicit `IsPublic` flag plus a random slug. - nginx is intended as the only production ingress to the API; the AI service is on a private backend-only network. - The API process owns database migrations/reconciliation and all seven workers; the current deployment assumes one API replica. ## Documentation-to-code differences observed during discovery - `job-tracker-ui/README.md` is obsolete Create React App boilerplate; the frontend now uses Next.js/Jest directly. - `docs/architecture/current.md` reports a smaller/older controller surface and stale file sizes; the current controller directory contains 29 controller classes plus partials/DTO files. - Root README API documentation omits substantial implemented surfaces including CV variants, billing, career profiles, AI workspace/history, job discovery, sessions, and several application-workspace APIs. - `deploy/README.md` recommends PostgreSQL, but the application implements SQLite and MariaDB/MySQL providers only. - Ignored local `vendor/`, `JobTrackerBackend/`, `.claude/worktrees/`, build outputs, databases, virtual environments, and frontend dependencies remain on disk but are not current tracked application source. ## Manual-audit exclusions - Generated/build/runtime: `.next/`, `out/`, `build/`, `node_modules/`, `bin/`, `obj/`, local databases, backups, keys, CV artifacts, test results, caches, and virtual environments. - Ignored historical/local copies: `.claude/worktrees/`, `JobTrackerBackend/`, `vendor/`, `tmp/`. - Archived documentation under `docs/_archive/` is historical evidence, not the current implementation contract. - Package lockfiles and EF generated migrations/model snapshot are reviewed for supply-chain and schema implications, not line-by-line as handwritten application logic. ## Unfinished-marker search No production-code `TODO`, `FIXME`, `HACK`, stub, or `NotImplementedException` was found outside deliberate test doubles, normal placeholder UI text, and a guided-acceptance script template. This does not prove feature completeness; incomplete behaviour is assessed through routes, tests, and browser journeys.